CVE-2024-6763

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/10/2024
Last modified:
10/07/2025

Description

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.<br /> <br /> The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI<br /> differs from the common browsers in how it handles a URI that would be <br /> considered invalid if fully validated against the RRC. Specifically HttpURI<br /> and the browser may differ on the value of the host extracted from an <br /> invalid URI and thus a combination of Jetty and a vulnerable browser may<br /> be vulnerable to a open redirect attack or to a SSRF attack if the URI <br /> is used after passing validation checks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* 7.0.0 (including) 9.4.57 (excluding)